Boot firmware corruption detection and mitigation
Abstract
An apparatus and method for providing access to reliable boot firmware. In various implementations, a computing system includes an integrated circuit with a security processor. Prior to performing any steps of a bootup operation using one of multiple copies of boot firmware, the security processor determines whether multiple signatures exist where the signatures are based on the multiple copies of boot firmware. Each of the multiple copies of boot firmware is a copy of a particular version of boot firmware. If the multiple signatures do not yet exist, then the security processor generates the signatures using the multiple copies of boot firmware. During a bootup operation, when the security processor determines that the multiple signatures already exist, the security processor uses these signatures to validate one or more of the multiple copies of boot firmware. The security processor continues with the bootup operation using the validated copy of boot firmware.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A security processor comprising:
circuitry;
wherein responsive to a first bootup operation and an existence of a plurality of signatures corresponding to a plurality of copies of boot firmware, the circuitry is configured to:
retrieve a first signature, of the plurality of signatures, corresponding to a first copy of boot firmware of the plurality of copies of boot firmware;
generate a second signature based on the first copy of boot firmware; and
execute the first bootup operation using the first copy of boot firmware, responsive to a match between the first signature and the second signature.
2. The security processor as recited in claim 1 , wherein an initial version of each of the plurality of copies of boot firmware is a same copy of a given boot firmware that performs initial steps of a bootup operation.
3. The security processor as recited in claim 2 , wherein each of the plurality of signatures is equal to a given signature generated by any one of the plurality of copies of boot firmware.
4. The security processor as recited in claim 1 , wherein in response to a second bootup operation, and a determination that the plurality of signatures corresponding to the plurality of copies of boot firmware do not exist, the circuitry is configured to generate a corresponding hash value for each of the plurality of copies of boot firmware.
5. The security processor as recited in claim 4 , wherein the circuitry is further configured to:
generate a corresponding signature for each hash value and store the corresponding signature in on-chip memory; and
execute the second bootup operation using one of the plurality of copies of boot firmware.
6. The security processor as recited in claim 2 , wherein in response to a second bootup operation, and an existence of the plurality of signatures corresponding to the plurality of copies of boot firmware, the circuitry is further configured to:
retrieve a third signature of the plurality of signatures corresponding to a second copy of boot firmware of the plurality of copies of boot firmware;
generate a fourth signature based on the second copy of boot firmware; and
continue generating and comparing signatures corresponding to the plurality of copies of boot firmware until a match is found for the third signature, in response to a mismatch between the third signature and the fourth signature.
7. The security processor as recited in claim 6 , wherein the circuitry is further configured to:
repair one or more of the plurality of copies of boot firmware using a third copy of boot firmware of the plurality of copies of boot firmware that provides a generated signature that matches the third signature; and
execute the second bootup operation using the third copy of boot firmware.
8. A method, comprising:
storing data by on-chip memory;
responsive to a first bootup operation and an existence of a plurality of signatures corresponding to a plurality of copies of boot firmware:
retrieving, by circuitry of a security processor, a first signature of the plurality of signatures corresponding to a first copy of boot firmware of the plurality of copies of boot firmware;
generating, by the security processor, a second signature based on the first copy of boot firmware; and
executing, by the security processor, the first bootup operation using the first copy of boot firmware, responsive to a match between the first signature and the second signature.
9. The method as recited in claim 8 , wherein an initial version of each of the plurality of copies of boot firmware is a same copy of a given boot firmware that performs initial steps of a bootup operation.
10. The method as recited in claim 9 , wherein each of the plurality of signatures is equal to a given signature generated by any one of the plurality of copies of boot firmware.
11. The method as recited in claim 8 , wherein in response to a second bootup operation, and a determination that the plurality of signatures corresponding to the plurality of copies of boot firmware do not exist, the circuitry is configured to generate a corresponding hash value for each of the plurality of copies of boot firmware.
12. The method as recited in claim 11 , further comprising:
generating, by the security processor, a corresponding signature for each hash value and store the corresponding signature in on-chip memory; and
executing the second bootup operation using one of the plurality of copies of boot firmware.
13. The method as recited in claim 9 , wherein in response to a second bootup operation, and an existence of the plurality of signatures corresponding to the plurality of copies of boot firmware, the method further comprises:
retrieving, by the security processor, a third signature of the plurality of signatures corresponding to a second copy of boot firmware of the plurality of copies of boot firmware;
generating, by the security processor, a fourth signature based on the second copy of boot firmware; and
continuing generating and comparing signatures corresponding to the plurality of copies of boot firmware until a match is found for the third signature, in response to a mismatch between the third signature and the fourth signature.
14. The method as recited in claim 13 , further comprising:
repairing, by the security processor, one or more of the plurality of copies of boot firmware using a third copy of boot firmware of the plurality of copies of boot firmware that provides a generated signature that matches the third signature; and
executing the second bootup operation using the third copy of boot firmware.
15. A computing system comprising:
on-chip memory configured to store data; and
a security processor comprising:
circuitry;
wherein responsive to a first bootup operation and an existence of a plurality of signatures corresponding to a plurality of copies of boot firmware, the circuitry is configured to:
retrieve a first signature of the plurality of signatures corresponding to a first copy of boot firmware of the plurality of copies of boot firmware;
generate a second signature based on the first copy of boot firmware; and
execute the first bootup operation using the first copy of boot firmware, responsive to a match between the first signature and the second signature.
16. The computing system as recited in claim 15 , wherein an initial version of each of the plurality of copies of boot firmware is a same copy of a given boot firmware that performs initial steps of a bootup operation.
17. The computing system as recited in claim 16 , wherein each of the plurality of signatures is equal to a given signature generated by any one of the plurality of copies of boot firmware.
18. The computing system as recited in claim 15 , wherein in response to a second bootup operation, and a determination that the plurality of signatures corresponding to the plurality of copies of boot firmware do not exist, the circuitry is configured to generate a corresponding hash value for each of the plurality of copies of boot firmware.
19. The computing system as recited in claim 18 , wherein the circuitry is further configured to:
generate a corresponding signature for each hash value and store the corresponding signature in on-chip memory; and
execute the second bootup operation using one of the plurality of copies of boot firmware.
20. The computing system as recited in claim 16 , wherein in response to a second bootup operation, and an existence of the plurality of signatures corresponding to the plurality of copies of boot firmware, the circuitry is further configured to:
retrieve a third signature of the plurality of signatures corresponding to a second copy of boot firmware of the plurality of copies of boot firmware;
generate a fourth signature based on the second copy of boot firmware; and
continue generating and comparing signatures corresponding to the plurality of copies of boot firmware until a match is found for the third signature, in response to a mismatch between the third signature and the fourth signature.Join the waitlist — get patent alerts
Track US12158956B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.